FTC Safeguards Rule for Arizona Tax Preparers: The 2026 Compliance Checklist

Why Arizona CPA Firms Can’t Ignore the FTC Safeguards Rule

If you’re running a CPA firm in Gilbert, Scottsdale, Mesa, or anywhere in the Phoenix metro area, the FTC Safeguards Rule applies to you. No size exemption. No grace period. Whether you’re a solo practitioner or a 50-person firm, the updated rule requires a documented information security program that protects client financial data.

The consequences of non-compliance aren’t theoretical. The FTC has been actively enforcing since June 2023, and firms that handle tax returns, financial statements, or any non-public personal information fall squarely under the rule’s definition of “financial institutions.”

This checklist breaks down exactly what your firm needs to have in place, with specific guidance for Arizona CPA firms navigating both federal FTC requirements and state-level obligations under ARS 18-552, Arizona’s 45-day breach notification law.

The 2026 Compliance Checklist

1. Designate a Qualified Individual

Your firm must name someone responsible for overseeing the information security program. This doesn’t have to be an employee. The FTC explicitly allows you to use a third-party provider, like a managed IT provider that specializes in CPA firms, to fill this role. But you, the firm, still carry the ultimate responsibility.

For most Arizona CPA firms with 5 to 20 employees, hiring a full-time CISO doesn’t make financial sense. Partnering with an IT provider who understands FTC Safeguards is the practical path.

2. Conduct a Written Risk Assessment

You need a documented risk assessment that identifies reasonably foreseeable internal and external risks to client information. This isn’t a one-time exercise. It needs to be reviewed and updated whenever your systems, processes, or threat landscape change significantly.

Your risk assessment should cover how client data is collected, stored, transmitted, and disposed of. Think about your tax software portals, client email communications, shared drives, and any cloud storage your team uses.

3. Implement Safeguards Based on Your Risk Assessment

Based on what your risk assessment identifies, you must implement controls. The updated rule specifically requires:

  • Access controls: Limit who can access client data based on job function
  • Data inventory: Know where all client information lives across your systems
  • Encryption: Encrypt client data both in transit and at rest
  • Multi-factor authentication (MFA): Required on every system that accesses client data, including tax software, email, and client portals
  • Secure disposal: Documented procedures for destroying client data when no longer needed

4. Build a Written Information Security Plan (WISP)

The Written Information Security Plan (WISP) is the backbone of your compliance program. It documents your security policies, procedures, and controls in a format that proves to the FTC (and the IRS, which requires WISPs under Publication 4557) that your firm takes data protection seriously.

Your WISP should be specific to your firm, not a generic template downloaded from the internet. It needs to reflect your actual systems, your actual risks, and your actual controls.

5. Monitor and Test Your Safeguards

Having controls in place isn’t enough. You need to test them. This means:

  • Regular vulnerability assessments of your network and systems
  • Penetration testing or continuous monitoring, depending on firm size
  • Reviewing access logs to ensure only authorized personnel are accessing client data
  • Testing your backup and disaster recovery procedures

For firms that want to stay ahead of compliance without managing this internally, cybersecurity services from a qualified provider can handle monitoring and testing on an ongoing basis.

6. Train Your Staff

Every person who touches client data needs security awareness training. This includes tax preparers, administrative staff, and anyone with access to your systems. Training should cover phishing recognition, password hygiene, secure file sharing, and your firm’s specific policies.

Training isn’t a one-and-done event. Schedule refresher sessions at minimum annually, and before tax season when the pressure to take shortcuts is highest. Check out our pre-tax season IT checklist for the full rundown.

7. Manage Your Service Providers

If you use third-party services like cloud hosting for tax software, client portals, payroll processors, or IT support, you need documented agreements that hold those providers to security standards consistent with the Safeguards Rule.

This means reviewing vendor security practices, requiring contractual data protection commitments, and periodically assessing whether your providers are meeting those commitments.

8. Create an Incident Response Plan

If client data is breached, you need a documented plan for how your firm will respond. This is especially critical in Arizona, where ARS 18-552 requires breach notification within 45 days, which is stricter than the federal 60-day standard.

Your incident response plan should identify who to contact (including the Arizona Attorney General’s office), how to contain the breach, how to notify affected clients, and how to prevent recurrence.

Arizona-Specific Considerations

Arizona CPA firms face a few unique compliance factors:

  • ARS 18-552: Arizona’s breach notification deadline is 45 days, tighter than the federal standard. Your incident response plan needs to account for this.
  • Extreme heat: Server rooms and network closets without proper cooling in Arizona summers (115°F+) accelerate hardware failure and create data loss risk.
  • Corporate relocations: Arizona’s booming business environment means firms are taking on more out-of-state clients, expanding the attack surface for remote access and data sharing.
  • IRS Publication 4557: In addition to FTC requirements, the IRS mandates WISPs for all tax preparers. Non-compliance can trigger IRS sanctions separate from FTC enforcement.

What Happens If You Don’t Comply

The FTC can impose fines, require corrective action, and publicly disclose enforcement actions. For small firms, the reputational damage alone can be devastating. And starting with tax year 2024, IRS Form W-12 Line 11 requires tax preparers to attest under penalty of perjury that they have a data security plan in place.

The recent ransomware attack on a CPA firm is a reminder that compliance isn’t just paperwork. It’s the difference between surviving an incident and losing your practice.

Getting Started

If your firm doesn’t have a documented security program yet, start with the risk assessment. It tells you where you stand and what needs to happen next. From there, build your WISP, implement the required controls, and establish ongoing monitoring.

Asteroid IT works with CPA firms across the Gilbert, Mesa, Scottsdale, and Phoenix metro area to build FTC-compliant security programs that work in practice, not just on paper. We handle the technical side so you can focus on your clients.

Call us at 480-937-7021 or schedule a conversation. No jargon, no pressure. Just a clear picture of what your firm needs.

Scroll to Top